Author: Preston St. Pierre
gstreamer, grep, flim, kdelibs, kdebase, selinux-policy-targeted,
xcdroast, udev, PHProjekt, nfs-utils, ncpfs, vim, evolution, mkdonline,
iproute, libpng, postgresql, IPSec, imlib, ruby, ncompress, and mod_ssl.
The distributors include Debian, Fedora, Gentoo, Mandrake, OpenBSD,
Red Hat, and TurboLinux.Detecting Physical Security Compromises
The first thing to always note is when your machine was rebooted.
Since Linux is a robust and stable OS, the only times your machine
should reboot is when you take it down for OS upgrades, hardware
swapping, or the like. If your machine has rebooted without you
doing it, that may be a sign that an intruder has compromised it.
Many of the ways that your machine can be compromised require the
intruder to reboot or power off your machine.
Check for signs of tampering on the case and computer area. Although
many intruders clean traces of their presence out of logs, it’s a
good idea to check through them all and note any discrepancy.
It is also a good idea to store log data at a secure location, such
as a dedicated log server within your well-protected network. Once
a machine has been compromised, log data becomes of little use as
it most likely has also been modified by the intruder.
The syslog daemon can be configured to automatically send log data
to a central syslog server, but this is typically sent unencrypted,
allowing an intruder to view data as it is being transferred. This
may reveal information about your network that is not intended to be
public. There are syslog daemons available that encrypt the data as
it is being sent.
Also be aware that faking syslog messages is easy — with an exploit
program having been published. Syslog even accepts net log entries
claiming to come from the local host without indicating their true
origin.
| Debian | ||
| Debian: zgv arbitrary code execution fix |
||
14th, December, 2004
|
||
| Debian: atari800 local root exploit fix | ||
14th, December, 2004
|
||
| Fedora | ||
| Fedora: MyODBC-2.50.39-18.2 update | ||
10th, December, 2004
|
||
| Fedora: MyODBC-2.50.39-19.1 update | ||
10th, December, 2004
|
||
| Fedora: mikmod-3.1.6-30.2 update | ||
13th, December, 2004
|
||
| Fedora: gstreamer-0.8.7-4.FC3.0 update | ||
14th, December, 2004
|
||
| Fedora: grep-2.5.1-31.2 update | ||
14th, December, 2004
|
||
| Fedora: flim-1.14.7-0.FC2 update | ||
15th, December, 2004
|
||
| Fedora: kdelibs-3.2.2-10.FC2 update | ||
15th, December, 2004
|
||
| Fedora: kdebase-3.2.2-8.FC2 update | ||
15th, December, 2004
|
||
| Fedora: kdelibs-3.3.1-2.4.FC3 update | ||
15th, December, 2004
|
||
| Fedora: kdebase-3.3.1-4.3.FC3 update | ||
15th, December, 2004
|
||
| Fedora: selinux-policy-targeted-1.17.30-2.51 update |
||
16th, December, 2004
|
||
| Fedora: xcdroast-0.98a15-8 update | ||
16th, December, 2004
|
||
| Fedora: udev-039-10.FC3.6 update | ||
16th, December, 2004
|
||
| Gentoo | ||
| Gentoo: PHProjekt setup.php vulnerability | ||
10th, December, 2004
|
||
| Gentoo: nfs-utils Multiple remote vulnerabilities | ||
13th, December, 2004
|
||
| Gentoo | ||
| Gentoo: ncpfs Buffer overflow in ncplogin and ncpmap |
||
15th, December, 2004
|
||
| Gentoo: vim, gVim Vulnerable options in modelines |
||
15th, December, 2004
|
||
| Mandrake | ||
| Mandrake: evolution various bugs fix | ||
14th, December, 2004
|
||
| Mandrake: mdkonline provide new features | ||
14th, December, 2004
|
||
| Mandrake: iproute2 temporary file vulnerability | ||
14th, December, 2004
|
||
| Mandrake: evolution various bugs fix | ||
14th, December, 2004
|
||
| Mandrake: libpng invalid zlib header problem fix |
||
14th, December, 2004
|
||
| Mandrake: postgresql temporary file vulnerability fix |
||
14th, December, 2004
|
||
| Mandrake: kde various bug fixes | ||
15th, December, 2004
|
||
| Mandrake: kdelibs & kdebase vulnerability fix |
||
15th, December, 2004
|
||
| OpenBSD: kernel heap overflow in IPsec | ||
14th, December, 2004
|
||
| Red Hat: imlib security vulnerabilities fix |
||
10th, December, 2004
|
||
| Red Hat: ruby denial of service issue fix |
||
13th, December, 2004
|
||
| Red Hat |
||
| Red Hat: ncompress security issue and bug fix |
||
13th, December, 2004
|
||
| Red Hat: apache and mod_ssl security vulnerabilities fix |
||
13th, December, 2004
|
||
| Red Hat: kernel security vulnerability fix |
||
13th, December, 2004
|
||
| Red Hat: Itanium security issues fix | ||
13th, December, 2004
|
||
| TurboLinux | ||
| TurboLinux: Security & Bugfix | ||
13th, December, 2004
|
||